Phishing for AWS credentials via AWS SSO device code authentication (updated 2024)
AWS SSO is vulnerable by design to device code authentication phishing, providing a powerful phishing vector for attackers.